Additional Microsoft Entra services and features related to identity, access, and network security
Monitoring Azure Environment
Denny Ahn
0
Reputation points
A subscription-level attack occurred in mid-December 2025, creating 231 VMs. Microsoft sent me an invoice a month later, which made me aware of the issue. It took nearly two months to investigate and resolve the issue.
I have configured a policy to restrict Azure VM creation. I'd like to monitor at the Subscription level, as attacks can come from other sources, not just the VM.
I want to prevent this from happening in the future. I want to configure Azure to alert me when activity is abnormal and protect my environment.
Thank you.
Microsoft Security | Microsoft Entra | Other
Microsoft Security | Microsoft Entra | Other
Sign in to answer